Search CMMI Consultant Blog

What is CMMC? The New Cybersecurity Maturity Model Certification from DOD with Latest Updates

CMMC (Cyber Maturity Model Certification) is a certification process developed by DOD (Department of Defense, USA) for its Contractors to ensure that they have the system for protection of sensitive data including Federal Contract Information and Controlled Unclassified Information. CMMC Model is based on the best-practices of different cyber security standards i.e. NIST 800 Standards, Federal Regulations, Defense Federal Acquisition Regulations Supplement (DFARS), UK’s Cyber Essentials and Australia’s Essential Eight. The CMMC previous version 0.4 was release on 30 August 2019. The New Draft Version 0.6 was released on 7 Nov 2019 with the significant changes in mode. This model is only up to Level 3. CMMC Model Ver. 0.6 contains following 4 Appendixes. Appendix A – CMMC Model 0.6, Appendix B – Level 1 description/clarification, Appendix C – Glossary and Appendix D – Acronym List. The Final Version 1.0 is expected to be released in January 2020.

CMMC Model Framework:

CMMC model framework is with 17 Domains at the top and is further supported by the number of capabilities under it. Each capability has number of process/practices it to be satisfied to achieve compliance (See Picture 1).

CMMC Domains:

17 Domains as mentioned in Model are as Under:

Access Control

Asset Management

Audit and Accountability

Awareness and Training

Configuration Management

Identification and Authentication

Incident Response

Maintenance

Media Protection

Personnel Security

Physical Security

Recovery

Risk Management

Security Assessment

Situational Awareness

Systems and Communications Protection

System and Information Integrity

CMMC Levels:

CMMC model is defined with 05 Levels for both practices and processes with Level 1 at the lowest (Basic) and Level 5 as highest (Optimized). The Details of each level is as under:

* Level 4&5 will be included in the future versions of CMMC Model.

Latest Update:

The CMMC Model Version 1.0 will be released in January 2020 with clarifications. Regarding Certification under this model currently DOD is developing the process of Accreditation. An RFI was brought out regarding this in previous months. Once the process of Accreditation will be finalized, an RFP for Accreditation Board selection will be brought out. After that the Accreditation Board will be selected. Then, the Accreditation Board will select the process for Third Party Accreditation Organization [TPAO]. This is expected to be complete by June 2020. Further details can be obtained from the FAQ’s on the website of Office of the Under Secretary of Defense for Acquisition & Sustainment Cybersecurity Maturity Model Certification.

References:

Information collected from Office of the Under Secretary of Defense for Acquisition & Sustainment Cybersecurity Maturity Model Certification and compiled by the author.